Reports & Testimonies
Recommendations Database
GAO’s recommendations database contains report recommendations that still need to be addressed. GAO’s priority recommendations are those that we believe warrant priority attention. We sent letters to the heads of key departments and agencies, urging them to continue focusing on these issues. Below you can search only priority recommendations, or search all recommendations.
Our recommendations help congressional and agency leaders prepare for appropriations and oversight activities, as well as help improve government operations. Moreover, when implemented, some of our priority recommendations can save large amounts of money, help Congress make decisions on major issues, and substantially improve or transform major government programs or agencies, among other benefits.
As of October 25, 2020, there are 4812 open recommendations, of which 473 are priority recommendations. Recommendations remain open until they are designated as Closed-implemented or Closed-not implemented.
Browse or Search Open Recommendations
Have a Question about a Recommendation?
- For questions about a specific recommendation, contact the person or office listed with the recommendation.
- For general information about recommendations, contact GAO's Audit Policy and Quality Assurance office at (202) 512-6100 or apqa@gao.gov.
Results:
Subject Term: "Security standards"
GAO-17-58, Feb 7, 2017
Phone: (202) 512-3841
Agency: Nuclear Regulatory Commission
Status: Open
Comments: In its February 26, 2018 report to Congress on actions NRC has taken in response to GAO recommendations, NRC continued to disagree with the recommendation to expand its existing data collection requirements or to transition such information from its existing NRC databases to the NSTS. NRC stated that, as required by 10 CFR Part 37, "Physical Protection of Category 1 and Category 2 Quantities of Radioactive Material," the NRC currently collects the number of shipments and mode of transport for domestic transfers, and the import and export of Category 1 quantities of radioactive material. Additionally, under the provisions of 10 CFR Part 110, "Export and Import of Nuclear Material," the NRC stated that it collects the number of shipments and mode of transport for the import and export of shipments containing Category 2 or higher quantities of radioactive material. The NRC stated that it is the agency's position that the current information collected provides the NRC with an understanding of the potential modes of transport for Category 1 and 2 quantities of radioactive material and existing regulatory requirements provide robust protection for all such modes. The NRC stated that it does not consider the proposed additional information collection activity to be of sufficient safety or security benefit to justify the associated regulatory actions it would require. In August 2019, and again in August 2020, the NRC reaffirmed its disagreement with this recommendation and that it did not intend to take action to implement it. Despite its disagreement with this recommendation, we will continue to monitor whether NRC takes any actions that would result in addressing the concern GAO raised.
GAO-16-686, Aug 26, 2016
Phone: (202) 512-6244
Agency: Executive Office of the President: Office of Management and Budget
Status: Open
Comments: The Office of Management and Budget (OMB) partially concurred with this recommendation, but does not intend to directly issue guidance as recommended. As of June 2020, OMB has not provided sufficient evidence that it has implemented this recommendation. We will continue to monitor OMB's implementation of this recommendation.
Agency: Department of Defense
Status: Open
Comments: In response to our report, DOD partially concurred with our recommendation; however, DOD subsequently concurred with the recommendation and is taking steps to implement it. The department stated that the issuance of an updated Cyber Incident Handling guidance is on track to be completed and coordinated in the third quarter of fiscal year 2018. As of June 2020, it has not yet provided sufficient evidence that it has implemented the recommendation. When we confirm what actions DOD has taken, we will provide updated information.
Agency: Department of State
Status: Open
Comments: The Department of State (State) concurred with this recommendation. However, as of June 2020, the department has not yet provided sufficient evidence that it has implemented the recommendation. When we receive additional evidence from State, we will review it to determine whether the department has addressed the recommendation.
Agency: Department of Transportation
Status: Open
Comments: The Department of Transportation (DOT) concurred with the recommendation and is currently updating its Cybersecurity Policy. The Department plans to be complete by June 29, 2019. As of June 2020, the department has not yet provided sufficient evidence that it has implemented the recommendation. Upon receiving additional evidence from DOT, we will review it to determine whether the department has addressed the recommendation.
Agency: Department of Transportation
Status: Open
Comments: The Department of Transportation (DOT) concurred with the recommendation and is currently updating its Cybersecurity Policy. The Department plans to be complete by June 29, 2019. As of June 2020, the department has not yet provided sufficient evidence that it has implemented the recommendation. Upon receiving additional evidence from DOT, we will review it to determine whether the department has addressed the recommendation.
Agency: National Aeronautics and Space Administration
Status: Open
Comments: The National Aeronautics and Space Administration (NASA) concurred with our recommendation. As of June 2020, NASA stated that the agency is working to update the relevant policy to address this recommendation, but the update is taking longer than expected; NASA expects the policy to be updated and the review process to be completed by November 30, 2020. We will examine the evidence when NASA provides it.